CVE-2003-0963

Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://marc.info/?l=bugtraq&m=107126386226196&w=2
http://marc.info/?l=bugtraq&m=107152267121513&w=2
http://marc.info/?l=bugtraq&m=107167974714484&w=2
http://marc.info/?l=bugtraq&m=107177409418121&w=2
http://marc.info/?l=bugtraq&m=107340499504411&w=2
http://secunia.com/advisories/10525
http://secunia.com/advisories/10548
http://www.debian.org/security/2004/dsa-406
http://www.mandriva.com/security/advisories?name=MDKSA-2003:116
http://www.novell.com/linux/security/advisories/2003_051_lftp.html
http://www.redhat.com/support/errata/RHSA-2003-403.html
http://www.redhat.com/support/errata/RHSA-2003-404.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180
ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://marc.info/?l=bugtraq&m=107126386226196&w=2
http://marc.info/?l=bugtraq&m=107152267121513&w=2
http://marc.info/?l=bugtraq&m=107167974714484&w=2
http://marc.info/?l=bugtraq&m=107177409418121&w=2
http://marc.info/?l=bugtraq&m=107340499504411&w=2
http://secunia.com/advisories/10525
http://secunia.com/advisories/10548
http://www.debian.org/security/2004/dsa-406
http://www.mandriva.com/security/advisories?name=MDKSA-2003:116
http://www.novell.com/linux/security/advisories/2003_051_lftp.html
http://www.redhat.com/support/errata/RHSA-2003-403.html
http://www.redhat.com/support/errata/RHSA-2003-404.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:alexander_v._lukyanov:lftp:2.3:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.4.9:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.5:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.6:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.7:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.8:*:*:*:*:*:*:*
cpe:2.3:a:alexander_v._lukyanov:lftp:2.6.9:*:*:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U - () ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U -
References () ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc - () ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc -
References () http://marc.info/?l=bugtraq&m=107126386226196&w=2 - () http://marc.info/?l=bugtraq&m=107126386226196&w=2 -
References () http://marc.info/?l=bugtraq&m=107152267121513&w=2 - () http://marc.info/?l=bugtraq&m=107152267121513&w=2 -
References () http://marc.info/?l=bugtraq&m=107167974714484&w=2 - () http://marc.info/?l=bugtraq&m=107167974714484&w=2 -
References () http://marc.info/?l=bugtraq&m=107177409418121&w=2 - () http://marc.info/?l=bugtraq&m=107177409418121&w=2 -
References () http://marc.info/?l=bugtraq&m=107340499504411&w=2 - () http://marc.info/?l=bugtraq&m=107340499504411&w=2 -
References () http://secunia.com/advisories/10525 - () http://secunia.com/advisories/10525 -
References () http://secunia.com/advisories/10548 - () http://secunia.com/advisories/10548 -
References () http://www.debian.org/security/2004/dsa-406 - () http://www.debian.org/security/2004/dsa-406 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2003:116 - () http://www.mandriva.com/security/advisories?name=MDKSA-2003:116 -
References () http://www.novell.com/linux/security/advisories/2003_051_lftp.html - () http://www.novell.com/linux/security/advisories/2003_051_lftp.html -
References () http://www.redhat.com/support/errata/RHSA-2003-403.html - () http://www.redhat.com/support/errata/RHSA-2003-403.html -
References () http://www.redhat.com/support/errata/RHSA-2003-404.html - () http://www.redhat.com/support/errata/RHSA-2003-404.html -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180 -

Information

Published : 2004-01-05 05:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0963

Mitre link : CVE-2003-0963

CVE.ORG link : CVE-2003-0963


JSON object : View

Products Affected

alexander_v._lukyanov

  • lftp